CVE-2017-1000251

HIGHCVSS 8/10EPSS 16.18%

Last modified

CVE-2017-1000251 is a high-severity vulnerability rated 8/10 on the CVSS scale. The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.. EPSS estimates a 16.18% chance of exploitation in the next 30 days.

Description

The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.

Metrics

CVSS 3.1
8/10

CVSS:3.1/AV:A/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
16.18%

96.5th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
LinuxLinux Kernel>= 2.6.32, < 3.2.94
LinuxLinux Kernel>= 3.3, < 3.16.49
LinuxLinux Kernel>= 3.17, < 3.18.71
LinuxLinux Kernel>= 3.19, < 4.1.45
LinuxLinux Kernel>= 4.2, < 4.4.88
LinuxLinux Kernel>= 4.5, < 4.9.50
LinuxLinux Kernel>= 4.10, < 4.12.13
LinuxLinux Kernel>= 4.13, < 4.13.2
DebianDebian Linux8.0
DebianDebian Linux9.0
NvidiaJetson Tk1r21
NvidiaJetson Tk1r24
NvidiaJetson Tx1r21
NvidiaJetson Tx1r24
RedhatEnterprise Linux Desktop6.0
RedhatEnterprise Linux Desktop7.0
RedhatEnterprise Linux Server6.0
RedhatEnterprise Linux Server7.0
RedhatEnterprise Linux Server Aus6.2
RedhatEnterprise Linux Server Aus6.4
RedhatEnterprise Linux Server Aus6.6
RedhatEnterprise Linux Server Aus7.2
RedhatEnterprise Linux Server Aus7.3
RedhatEnterprise Linux Server Aus7.4
RedhatEnterprise Linux Server Aus7.6
RedhatEnterprise Linux Server Aus7.7
RedhatEnterprise Linux Server Eus6.7
RedhatEnterprise Linux Server Eus7.2
RedhatEnterprise Linux Server Eus7.3
RedhatEnterprise Linux Server Eus7.4
RedhatEnterprise Linux Server Eus7.5
RedhatEnterprise Linux Server Eus7.6
RedhatEnterprise Linux Server Eus7.7
RedhatEnterprise Linux Server Tus6.5
RedhatEnterprise Linux Server Tus6.6
RedhatEnterprise Linux Server Tus7.2
RedhatEnterprise Linux Server Tus7.3
RedhatEnterprise Linux Server Tus7.4
RedhatEnterprise Linux Server Tus7.6
RedhatEnterprise Linux Server Tus7.7
RedhatEnterprise Linux Workstation6.0
RedhatEnterprise Linux Workstation7.0

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2017-1000251?
The native Bluetooth stack in the Linux Kernel (BlueZ), starting at the Linux kernel version 2.6.32 and up to and including 4.13.1, are vulnerable to a stack overflow vulnerability in the processing of L2CAP configuration responses resulting in Remote code execution in kernel space.
How severe is CVE-2017-1000251?
CVE-2017-1000251 has a CVSS score of 8/10 (HIGH severity). The EPSS model estimates a 16.18% probability of exploitation in the next 30 days.
How do I fix CVE-2017-1000251?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2017-1000251?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST